How we built Enclaves: Egress Networking
Blog post from Evervault
Evervault has introduced Enclaves, designed to facilitate the deployment of applications within a Confidential Computing environment, specifically using AWS Nitro Enclaves. This initiative addresses the initial limitations of Nitro Enclaves, which lack inherent networking capabilities, by enabling optional egress traffic to support a wider variety of applications, such as card payments and blockchain transactions. Initially, the development team experimented with DNS spoofing and SNI-based routing to manage egress networking but found these methods insufficient for scalability and flexibility, prompting a redesign. By leveraging iptables, Evervault refined the egress networking process, allowing traffic redirection without binding to multiple ports and removing the dependency on SNI, thus supporting a broader range of protocols. The new approach also involves caching DNS results to handle dynamic IP changes and implements domain and IP allowlisting to prevent potential supply chain attacks. Overall, these improvements have resulted in a more extensible, user-friendly system that does not confuse users with DNS spoofing or waste resources, while also supporting a wider range of use cases.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.